PT-2023-11526 · Suricata+3 · Suricata+3
Nguyen Quoc Viet
+1
·
Publicado
2013-12-28
·
Atualizado
2025-02-12
·
CVE-2020-19678
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pfsense version 2.1.3
Pfsense Suricata version 1.4.6 pkg version 1.0.1
Description
A Directory Traversal issue allows a remote attacker to obtain sensitive information via the
file parameter to the "suricata/suricata logs browser.php" endpoint. This enables access to files outside the intended directory, potentially revealing confidential data.Recommendations
For Pfsense version 2.1.3, update to a version that fixes this issue.
For Pfsense Suricata version 1.4.6 pkg version 1.0.1, update to a version that fixes this issue.
As a temporary workaround, consider restricting access to the "suricata/suricata logs browser.php" endpoint to minimize the risk of exploitation.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Pfsense
Pfsense Suricata
Suricata